Missing Authentication for Message Server Internal Registration
SAP NetWeaver AS (Message Server)
The Message Server is the registration broker for every application server in your SAP landscape. If an attacker can register a rogue app server they sit in the middle of your ABAP traffic. This class of vulnerability has been a known attack vector since 2021. If your Message Server port is reachable from outside the SAP network segment, treat this as a zero-day and act now.
Vulnerability Detail
Insufficient validation of authenticity of application server components during internal registration. An unauthenticated remote attacker could register a rogue application server into the SAP system group, enabling traffic interception and potential remote code execution.
Patch Action
Apply the kernel patch from SAP Note 3759472. Verify Message Server internal port (3600/3900) is firewalled and not reachable from untrusted networks as a compensating control.
Affected Versions
Patch Info